A vulnerability identified as critical has been detected in mooSocial up to 3.2.4. This issue affects some unknown processing of the file /stores/all-products. Performing a manipulation of the argument rating results in sql injection. This vulnerability was named CVE-2026-105149. The attack may be initiated remotely. In addition, an exploit is... Weiterlesen: CVE-2026-105149 | mooSocial up to 3.2.4 /stores/all-products rating s…
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-105149 | mooSocial up to 3.2.4 /stores/all-products rating sql injection (EUVD-2026-92095)
A vulnerability identified as critical has been detected in mooSocial up to 3.2.4. This issue affects some unknown processing of the file /stores/all-products.…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
NVD Primärbewertung & CISA SSVCCVE-2026-105149
NVD: DeferredNVD 7.3 · HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
NVD-Datenstand: 06.10.2026, 22:17 UTC
Ausnutzung beobachtet: Nein Automatisierbar: Ja Technischer Impact: Teilweise
CISA-SSVC-Triage (vulnrichment)CVE-2026-105149
Exploitation: none (Keine bekannte Ausnutzung)Automatable: yes (Automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2026-10-06T21:56:04.944885Z · CISA Coordinator
Advisory Radar
In herstellerseitiger Prüfung
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):